← Back to AI Legal Lab
Insight
AI Service LegalLegal Outsourcing

Initial Response to a Personal Data Breach: Reporting Deadlines and a Timeline of What to Do

Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.

When you receive a report suggesting that personal data may have been leaked, proceed in parallel with stopping the damage from spreading and checking whether the incident falls within the statutory reporting obligations. The reporting deadline runs not from the day the incident itself occurred, but from the day you became aware of a reportable situation. Whatever the route of discovery, whether misdirected transmissions, unauthorized access or a notice from a contractor, you need to record who learned what and when.

The Two-Stage Reporting Obligation and the Four Reportable Categories

Article 26 of the Act on the Protection of Personal Information (APPI) requires business operators handling personal information to report to the Personal Information Protection Commission when a leak or similar incident involving personal data occurs that is highly likely to harm individuals' rights and interests. Paragraph 2 of that Article also sets out an obligation to notify the individuals concerned.

As a rule, this report is made in two stages: a preliminary report and a final report. Under the Commission's practice, after discovery you first submit a preliminary report promptly (generally within three to five days) covering what is known at that point, and then submit a final report. Where all the information is available from the outset, a single report serving both purposes is also permitted, but delaying the preliminary report to wait for the cause to be identified is not in line with the purpose of the system.

The reportable situations are the following four categories set out in Article 7 of the Enforcement Rules of the APPI.

  • A leak or similar incident involving personal data that includes special care-required personal information
  • A leak or similar incident involving personal data whose unauthorized use may cause financial damage
  • A leak or similar incident involving personal data caused by an act that may have been committed for a wrongful purpose
  • A leak or similar incident affecting more than 1,000 individuals

A "leak or similar incident" here includes not only leaks but also loss of or damage to data, and situations in which any of these may have occurred. Even at a stage where there is no proof of an outflow, begin considering whether a report is required. On the other hand, where measures necessary to protect individuals' rights and interests have been taken, such as advanced encryption, a report may not be required. This exclusion is not limited to the category of special care-required personal information. Make the determination after checking the encryption method and the state of key management.

In the category of acts committed for a wrongful purpose, personal information that the business intends to handle as personal data, such as information it is in the process of acquiring, is also included. In a case where an attacker obtained information entered into a web form, the incident cannot be excluded merely because the information had not yet been stored in the company's database. Confirm these scopes in accordance with sections 3-5-1 and 3-5-3 of the Commission's Guidelines (General Rules) (Japanese).

What is counted under Article 7, Item 4 of the Enforcement Rules is the number of individuals whose personal data has been, or may have been, the subject of the leak or similar incident. It is not determined by the number of recipients of a misdirected transmission. If the number of such individuals exceeds 1,000, the incident falls under that Item, and even where the number is small, a reporting obligation arises if the incident falls under another reportable category, such as a leak of special care-required personal information or a leak that may have been committed for a wrongful purpose.

Deadline for the Final Report and Decisions on Notifying Individuals and Public Announcement

Under Article 8 of the Enforcement Rules, the deadline for submitting the final report is, as a rule, within 30 days from the day you became aware of the reportable situation. However, where the incident falls under Article 7, Item 3 of the Enforcement Rules (a leak or similar incident caused by an act for a wrongful purpose), the deadline is within 60 days. Where the incident falls under this category and also under the categories of special care-required personal information or more than 1,000 individuals, the deadline for the final report is likewise within 60 days. In this case too, the preliminary report must be submitted promptly.

For a corporation, the point of "becoming aware" from which the period runs is the point at which any of its departments became aware of the reportable situation. The starting point cannot be pushed back to the day on which management or the legal department learned of it. Section 3-5-3-4 of the General Rules (Japanese) states that that day is counted as day 1, and that Saturdays, Sundays and public holidays are included in the count. If the 30th or 60th day falls on a day on which government offices are closed, the deadline is the next day on which they are open.

As a rule, the final report must state all reportable matters. If some matters remain unknown despite reasonable efforts, you report what you have ascertained by the deadline and submit an additional report as soon as the remaining matters become clear. For matters not yet known, keeping a record of the scope already investigated and the investigations that remain can also be used in explaining matters to the Commission.

Notification to individuals is made promptly according to the circumstances of the situation, under Article 26, Paragraph 2 of the Act and Article 10 of the Enforcement Rules. You cannot wait until the same 30 or 60 days applicable to the final report to the Commission. Inform individuals of what they need to know to prevent harm, such as the items of information leaked and the risk of secondary damage. Where, for example, the notification itself may cause the damage to spread, decide on the timing based on the facts already ascertained and the effect of the notification.

Alternative measures in place of notification may be taken where notifying the individual is difficult and measures necessary to protect the individual's rights and interests are taken. Section 3-5-4-5 of the General Rules gives as examples cases where the business does not hold contact details, or where the contact details are outdated and the individual cannot be reached. Do not switch uniformly to public announcement merely because the number of affected individuals is large; consider the circumstances making notification difficult and whether a public announcement or an inquiry desk can protect the individuals.

Initial Response Immediately After Discovery and Preservation of Evidence

The practical work to begin within the first few days after discovery mainly comes down to the following three points.

First, report internally to the person in charge and prevent the damage from spreading. Immediately take measures suited to the case, such as cutting off the network connection of a server that was accessed without authorization, suspending the relevant accounts, asking recipients of misdirected data to delete it, and remotely locking a lost device. Decide which information systems department will handle recovery and which department will handle reporting and notification, and collect the information ascertained into a single record.

Next, proceed with ascertaining the facts. Write out in chronological order the items of information leaked, the number of affected individuals, the time of occurrence, the presumed cause and so on. Separate facts from speculation, and mark unconfirmed items as under investigation. In addition to these, the preliminary report should state what is known about each of the matters in Article 8, Paragraph 1 of the Enforcement Rules, such as the risk of secondary damage, the response to individuals, public announcement and the status of measures to prevent recurrence.

In parallel, preserve evidence such as logs, access histories and transmission records. If logs are overwritten by recovery work or configuration changes, it becomes difficult to identify the cause later. While giving top priority to preventing damage, it is essential to proceed carefully so as not to erase objective records.

Prepare the notification to individuals and the public announcement based on this record. Do not state definitively a cause that is still under investigation, or write that "there is no secondary damage" at a stage where this has not been confirmed; indicate the scope that has been confirmed and how further information will be provided. If you decide in advance who will verify the facts internally and who will approve the public announcement, it becomes easier to update the explanation when additional facts come to light.

Leaks at Contractors and Dealing with Regulators

Where a reportable leak or similar incident occurs at a contractor, as a rule both the entrusting party and the contractor have a reporting obligation, and a joint report is also possible. The proviso to Article 26, Paragraph 1 of the Act and Article 9 of the Enforcement Rules exempt the contractor from its reporting obligation where, after becoming aware of the situation, it promptly notifies the entrusting party of the reportable matters it has ascertained. Do not assume that simply informing the entrusting party of the incident is enough; check the content and timing of the notification.

Where this exception is used, it is the entrusting party that bears the obligation to report to the Commission. In the outsourcing agreement, set out the point of contact when a suspected incident comes to light, the matters to be reported in the first notice, and cooperation in preserving and providing logs. In my view, it is advisable to agree on consultation before public announcement while ensuring that reports and notifications required by law are not delayed while waiting for the other party's consent.

Even after submitting the final report, you may receive additional questions, guidance or recommendations from the Commission. For this reason, it is effective in practice to compile countermeasures that cover not only technical measures to prevent recurrence but also issues in the management system, such as why discovery was delayed. So as not to panic in an emergency, it is desirable to document in ordinary times the initial response procedures, such as who receives the first report and who determines the reportable category.

Keywords
Personal data
Browse all keywords

Related articles

Articles connected to this topic.

Insight / 2026.09.20 The Amended Act on the Protection of Personal Information: Where Things Stand After Promulgation and What Companies Should Prepare Insight / 2026.08.01 Training Dataset License Agreements: Dividing Rights Between the Data Provider and the Developer Insight / 2026.07.10 Always Check Article Numbers and Sources Yourself: A Pitfall of Generative AI

Services connected to this topic

Legal outsourcing Ongoing legal team support for contract review and legal operations. Generative AI legal consulting Terms, privacy, copyright, AI governance, and internal AI use rules.
View AI Legal Lab articles